VDB
Sign up
—

RUSTSEC-2026-0128

Double-free and use-after-free in `Keys::next()`

Details

`Keys::next()` uses `ptr::read` to move out the `Option<V>` by value, which drops the contained `V` when `V` is non-Copy (e.g. `String`). This leaves a dangling value in the map's storage slot. Subsequent `get()` operations on that key return a dangling reference to already-freed memory.

This can be triggered through safe public APIs — `Map::keys()`, `Keys::next()`, and `Map::get()` — with no `unsafe` required from the caller. Under Miri, accessing the freed slot produces "Undefined Behavior: pointer not dereferenceable: alloc has been freed, so this pointer is dangling".

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/emap
Introduced in: 0.0.0-0

No fixed version published yet for emap. Pin to a known-safe version or switch to an alternative.

References